QID 730016
Date Published: 2021-04-06
QID 730016: SimpleSAMLphp Reflected Cross-Site-Scripting Vulnerability(201907-01)
SimpleSAMLphp is an award-winning application written in native PHP that deals with authentication.
Affected Versions:
SimpleSAMLphp prior to 1.17.3.
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of SimpleSAMLphp
If metadata is consumed for a rogue entity that includes javascript code in the corresponding endpoints, this javascript code might be run by users trying to access this entity.
Solution
Customers are advised Upgrade to the latest version of SimpleSAMLphp. For more information please visit 201907-01
Vendor References
- 201907-01 -
simplesamlphp.org/security/201907-01
CVEs related to QID 730016
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 201907-01 |
|